Phishing for AWS credentials via AWS SSO device code authentication (updated 2024)

AWS SSO is vulnerable by design to device code authentication phishing, providing a powerful phishing vector for attackers.